CVE-2025-56396: Ruoyi

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.

Affected products

  • Ruoyi Ruoyi: version 4.8.1 only

Published 2025-11-26. Last modified 2026-06-17.